Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TidePool offers many capabilities typical of most RATs... TidePool is embedded within an MHTML document that exploits CVE-2015-2545. | TidePool is embedded within an MHTML document that exploits CVE-2015-2545.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TidePool offers many capabilities typical of most RATs... TidePool is embedded within an MHTML document that exploits CVE-2015-2545.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TidePool is a backdoor malware, evolved from BS2005, used by APT15 for espionage against diplomatic targets.
Trojan with RAT-like capabilities that can manipulate files, execute commands via named pipes, gather host information, encode data in base64, and exfiltrate it over HTTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.